Executive brief
A vulnerability in the Linux kernel's Near Field Communication (NFC) component could allow a malicious nearby device to crash the system. By sending specially crafted, empty data packets, an attacker can trigger a system panic or read sensitive information from the computer's memory. This affects devices using NFC functionality and could lead to a complete service outage or local data exposure.
Technical details
An out-of-bounds (OOB) heap read vulnerability exists in the Linux kernel NFC subsystem within the HCP (Host Controller Protocol) header parsing logic. Specifically, the functions nfc_hci_recv_from_llc() and nci_hci_data_received_cb() fail to validate that the incoming socket buffer (skb) contains at least one byte before accessing the packet header. A malicious NFC peer can transmit a 0-byte HCP frame that bypasses the SHDLC layer, leading to an OOB read. Furthermore, if such a frame is processed as a non-final fragment, it causes a message length underflow to UINT_MAX, resulting in a kernel panic (skb_over_panic) during reassembly. The issue has been addressed by implementing pskb_may_pull() checks to ensure minimum buffer lengths before header access.
Affected products
- Linux Linux Kernel 8b8d2e08bf0d to f040e590c035bfd9553fe79ee9585caf1b14d67b
Timeline
- 2026-05-05: other: Vulnerability reported by researcher
- 2026-06-09: patched: Fix committed to stable kernel trees
- 2026-07-19: disclosed: CVE published
References
- https://git.kernel.org/stable/c/1905f5ec3641b2b234bb63549c8ca11ab85466eb
- https://git.kernel.org/stable/c/22d41b176b9989efd21c3b2d3abf6728f05b9d9a
- https://git.kernel.org/stable/c/37382293f174b82a0616c8295e32b1fc8e13d1ed
- https://git.kernel.org/stable/c/83b1362edc9d6ae376c6f36da116e2c70f2e70a6
- https://git.kernel.org/stable/c/b99366d74b535d0cadb1ef73e04639415d9ff3b7
- https://git.kernel.org/stable/c/c4cc6b3b0013acb3ed0b2b60e57dfae98647fe98
- https://git.kernel.org/stable/c/ed6d5d97dad0334a7f43d218753429cbe2f70a4f